Skip to content

fix: axios and qs package bump#106

Merged
ajasnosz merged 1 commit into
developfrom
fix/bump-packages
Jun 29, 2026
Merged

fix: axios and qs package bump#106
ajasnosz merged 1 commit into
developfrom
fix/bump-packages

Conversation

@ajasnosz

Copy link
Copy Markdown
Contributor
  • Bump axios from ^1.6.8 to ^1.16.0 (resolves HIGH CVEs: prototype pollution, proxy-auth credential leak, ReDoS, SSRF)
  • Bump qs from 6.15.1 to 6.15.2 (resolves MODERATE CVE-2026-8723: DoS via stringify)
  • Add yarn resolutions to force patched versions of transitive deps pulled through lerna>nx: axios, undici, tmp, form-data, brace-expansion, yaml, tar, js-yaml

@ajasnosz ajasnosz merged commit 12f5518 into develop Jun 29, 2026
4 checks passed
@ajasnosz ajasnosz deleted the fix/bump-packages branch June 29, 2026 07:59
splunk-ta-helper Bot pushed a commit that referenced this pull request Jun 29, 2026
## [1.2.2-beta.1](v1.2.1...v1.2.2-beta.1) (2026-06-29)

### Bug Fixes

* axios and qs package bump ([#106](#106)) ([12f5518](12f5518))
@splunk-ta-helper

Copy link
Copy Markdown

🎉 This PR is included in version 1.2.2-beta.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

ajasnosz added a commit that referenced this pull request Jun 29, 2026
* fix: axios and qs package bump (#106)

* chore(release): 1.2.2-beta.1

## [1.2.2-beta.1](v1.2.1...v1.2.2-beta.1) (2026-06-29)

### Bug Fixes

* axios and qs package bump ([#106](#106)) ([12f5518](12f5518))

---------

Co-authored-by: srv-rr-github-token <94607705+srv-rr-github-token@users.noreply.github.com>
splunk-ta-helper Bot pushed a commit that referenced this pull request Jun 29, 2026
## [1.2.2](v1.2.1...v1.2.2) (2026-06-29)

### Bug Fixes

* axios and qs package bump ([#107](#107)) ([4ddd636](4ddd636)), closes [#106](#106) [#106](#106)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants